Link to home
Start Free TrialLog in
Avatar of kdschool
kdschool

asked on

TLS 1.1 Should I use QWORD or DWORD and what ciphers should be added ?

Windows 2008 R2 server, IIS 7.0.  I turned off the SSL 3.0 and turned on the TLS 1.1 in the registiry using the Microsoft instructions.  They scanned the server again and they are saying it's still  vunerable.

I used QWORD in the registry settings instead of DWORD since it's a 64 bit operating system.  Is QWORD Correct?

I was not sure if there were specific ciphers I needed to turn off also that may still be causing the problem?
SOLUTION
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I gave up using manual registry entries.
Try this free tool instead:

https://www.nartac.com/Products/IISCrypto/

Simon.
Avatar of btan
btan

there is also some sharing of key note running reg, pls see in SAN posting (esp the feedbacks)
https://isc.sans.edu/forums/diary/POODLE+Turning+off+SSLv3+for+various+servers+and+client/18837
Avatar of kdschool

ASKER

Can't use a tool through the firewall.  Thank you so much for the images.  That was spot on.